High severity7.5NVD Advisory· Published Mar 2, 2023· Updated Jun 17, 2026
CVE-2023-0053
CVE-2023-0053
Description
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive information such as user credentials to gain access to the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:sauter-controls:bacnetstac:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sauter-controls:bacnetstac:*:*:*:*:*:*:*:*range: <=4.2.1
- (no CPE)range: <4.2.1
- cpe:2.3:o:sauter-controls:modunet300_ey-am300f001_firmware:*:*:*:*:*:*:*:*Range: <=3.3-006
- cpe:2.3:o:sauter-controls:modunet300_ey-am300f002_firmware:*:*:*:*:*:*:*:*Range: <=3.3-006
- cpe:2.3:o:sauter-controls:nova_106_eyk300f001_firmware:*:*:*:*:*:*:*:*Range: <=3.3-006
- cpe:2.3:o:sauter-controls:nova_220_eyk220f001_firmware:*:*:*:*:*:*:*:*Range: <=3.3-006
- cpe:2.3:o:sauter-controls:nova_230_eyk230f001_firmware:*:*:*:*:*:*:*:*Range: <=3.3-006
- Range: <=3.3-006
- Range: Firmware all versions
- Range: Firmware all versions
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-23-012-05nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.